AspisAI: A Canonical, Machine-Interpretable Governance Framework for Automated Multi-Standard Compliance Monitoring

📅 2026-09-09
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出AspisAI框架,通过将多种标准要求转化为机器可解释的模型并评估证据,解决多标准合规监测成本高、一致性差的问题。
📝 Abstract
Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework~2.0, Cyber Essentials, and the GDPR. In practice, these obligations are managed through manual mappings, spreadsheet-based tracking, and periodic audits that are costly to maintain, inconsistent across standards, and weak in traceability. This paper presents \emph{AspisAI}, a bounded, standard-agnostic governance framework that translates selected requirements from several frameworks into a canonical, machine-interpretable control model, and evaluates submitted evidence against condition-based decision rules to produce explainable, traceable compliance determinations. Within a bounded scope of 26 representative requirements, the framework is evaluated in a controlled simulation against five governance-oriented criteria and, critically, against two external reference points that mitigate the circularity of single-author evaluation: its cross-standard mappings are validated against NIST's own published informative references, with 57\,\% exact agreement and divergences confined to same-family controls, and the framework is applied to real third-party evidence from the OpenSSF Scorecard, surfacing genuine governance gaps in a live open-source project. The controlled results, comprising full requirement encoding, 88.5\,\% mapping coverage, complete traceability, and correct detection of all introduced gaps, establish functional correctness, while the external validation provides evidence of applicability beyond the simulation. The contribution is therefore a demonstration that a canonical, provenance-preserving governance model can render multi-standard compliance both automatable and auditable.
Problem

Research questions and friction points this paper is trying to address.

cybersecurity
privacy standards
compliance monitoring
traceability
multi-standard
Innovation

Methods, ideas, or system contributions that make the work stand out.

canonical control model
machine-interpretable
multi-standard compliance
automatable and auditable
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
T
Tsafac Nkombong Regine Cyrille
CyberMACS, Applied Cybersecurity
H
Hasan Dag
Kadir Has University
Reiner Creutzburg
Reiner Creutzburg
SRH University of Applied Sciences Heidelberg
K
Knut Haufe
SRH University of Applied Sciences Heidelberg